US11245581B2

Selective event stream data storage based on historical stream data

Summary by NHIP

Storage percentage calculation

The method calculates a storage percentage for an event stream based on historical usage data relative to a storage limit. It determines this percentage to store only a portion of the stream in data stores while generating the historical data without storing the stream segments used for that calculation.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

The disclosed embodiments provide a system that facilitates the processing of network data. During operation, the system causes for display a graphical user interface (GUI) for configuring the generation of time-series event data from network packets captured by one or more remote capture agents. Next, the system causes for display, in the GUI, a first set of user-interface elements containing a set of statistics associated with one or more event streams that comprise the time-series event data. The system then causes for display, in the GUI, one or more graphs comprising one or more values from the set of statistics. Finally, the system causes for display, in the GUI, a value of a statistic from the set of statistics based on a position of a cursor over the one or more graphs.

US11245581B2, drawing sheet 1
Sheet 1 of 50

Term

8.4 yearsleft in the term

Expires 24 February 2035, including 315 days of term adjustment.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

29 claims: 3 independent, 26 dependent

  1. 1
    Broadest claimClaim Score 48, average(NHIP)A method performed by a configuration server coupled via a network to at least one remote capture agent, the method comprising:receiving an event stream from a remote capture agent of the at least one remote capture agent, the event stream including timestamped event data generated by the at least one remote capture agent based on network traffic monitored by the remote capture agent;identifying historical data indicating an amount of storage used by the event stream over one or more periods of time;calculating, based on the historical data, an expected amount of storage to be used by the event stream relative to a storage limit;determining a percentage of the event stream to store in one or more data stores based on the expected amount of storage to be used by the event stream relative to the storage limit;and causing a portion of the event stream to be stored in the one or more data stores according to the percentage.
  2. 28
    An apparatus, comprising:one or more processors;and memory storing instructions that, when executed by the one or more processors, cause the apparatus to: receive an event stream from a remote capture agent of the at least one remote capture agent, the event stream including timestamped event data generated by the at least one remote capture agent based on network traffic monitored by the remote capture agent;identify historical data indicating an amount of storage used by the event stream over one or more periods of time;calculate, based on the historical data, an expected amount of storage to be used by the event stream relative to a storage limit;determine a percentage of the event stream to store in one or more data stores based on the expected amount of storage to be used by the event stream relative to the storage limit;and cause a portion of the event stream to be stored in the one or more data stores according to the percentage.
  3. 29
    A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform operations comprising:receiving an event stream from a remote capture agent of the at least one remote capture agent, the event stream including timestamped event data generated by the at least one remote capture agent based on network traffic monitored by the remote capture agent;identifying historical data indicating an amount of storage used by the event stream over one or more periods of time;calculating, based on the historical data, an expected amount of storage to be used by the event stream relative to a storage limit;determining a percentage of the event stream to store in one or more data stores based on the expected amount of storage to be used by the event stream relative to the storage limit;and causing a portion of the event stream to be stored in the one or more data stores according to the percentage.